Ask the Community
Groups
CVE-2013-6438 httpd: mod_dav denial of service via crafted DAV WRITE request - Connect IT Community | Kaseya
<main> <article class="userContent"> <h3 data-id="cve-id"><strong>CVE ID</strong></h3> <p>CVE-2013-6438</p> <h3 data-id="description"><strong>DESCRIPTION</strong></h3> <p>The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attackers to cause a denial of service (daemon crash) via a crafted DAV WRITE request.<br><br>Unitrends risk assessment: None if security updates applied<br> </p> <h3 data-id="resolution"><strong>RESOLUTION</strong></h3> <p>For CentOS6, Unitrends systems have httpd-2.2.15-54.el6.centos or later, <br>and this issue was fixed in httpd-2.2.15-30.el6_5<br>For CentOS5, </p> <h3 data-id="link-to-advisories"><strong>LINK TO ADVISORIES</strong></h3> <p></p> <ul><li><a rel="nofollow" href="/home/leaving?allowTrusted=1&target=https%3A%2F%2Faccess.redhat.com%2Fsecurity%2Fcve%2Fcve-2013-6438%250D%250Ahttps%3A%2F%2Faccess.redhat.com%2Ferrata%2FRHSA-2014%3A0370">https://access.redhat.com/security/cve/cve-2013-6438 https://access.redhat.com/errata/RHSA-2014:0370</a></li></ul> </article> </main>